Privacy Notice

Last updated: 14 June 2026

Who we are

CareLedgerPro is provided by Litania Healthcare Professional Services Ltd as a data processor to care providers. The care provider using CareLedgerPro is the data controller for personal data about their residents, staff, and contacts. CareLedgerPro is designed to support Controllers in meeting their obligations under UK GDPR and the Data Protection Act 2018.

The data we process

We process the following categories of personal data:

  • Service user identity details and the houses or units they live in.
  • Financial records, including balances, transactions, petty cash, receipts and signatures relating to each service user's money.
  • Staff account details, roles and access assignments.
  • Audit logs recording who accessed or changed records and when.

Some records may include health, capacity or care-related information that may be special category data depending on context.

Why we process it

We process this data to:

  • meet our legal and regulatory obligations as a care provider;
  • safeguard service-user finances and support the delivery of care services;
  • maintain accurate financial and care records; and
  • support accountability and oversight.

Where required, we rely on a lawful basis under UK GDPR, including Article 6(1)(c) and, where appropriate, Article 6(1)(e) or Article 6(1)(f). Where special category data is involved, we apply an additional condition under Article 9 where appropriate and lawful. We do not use your data for marketing.

How we keep it secure

We use a range of technical and organisational measures to help protect your data, including:

  • role-based access, so staff only see service users they are assigned to;
  • append-only audit logs recording access and changes;
  • encryption in transit and at rest;
  • password checks against known leaked-password databases; and
  • transaction controls that allow entries to be voided with a reason, but not silently deleted.

How long we keep it

We keep financial and care-related records only for as long as necessary, in line with our approved retention schedule and applicable legal, regulatory and operational requirements.

Financial records are normally retained for at least 7 years. Care-related records are retained for the period set out in the relevant records management guidance or our approved retention schedule, after which they are securely destroyed.

Your rights

Under UK data protection law, you may have the right to:

  • access your data;
  • request rectification of inaccurate or incomplete data;
  • request erasure in some circumstances;
  • restrict how we process your data;
  • object to certain processing; and
  • request data portability in some cases.

Some rights may be limited where we must keep records for legal, safeguarding or regulatory reasons. To exercise your rights, contact the care provider's Data Protection Officer or privacy contact.

You also have the right to complain to the Information Commissioner's Office (ICO).

Cookies

We use only essential cookies needed to keep you securely signed in. We do not use advertising or third-party tracking cookies.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.